CVE-2025-53701 - CVE House
Back to Database
Status published Medium CVE-2025-53701

XSS vulnerability in Vilar VS-IPC1002 IP cameras

Vulnerability Description

Vilar VS-IPC1002 IP cameras are vulnerable to Reflected XSS (Cross-site Scripting) attacks, because parameters in GET requests sent to /cgi-bin/action endpoint are not sanitized properly, making it possible to target logged in admin users. The vendor did not respond in any way. Only version 1.1.0.18 was tested, other versions might be vulnerable as well.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-53701

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Szymon Paszun

Affected Vendor

Affected Software

VS-IPC1002
Vulnerable Versions:
1.1.0.18

Timeline

Official Publish: October 23rd, 2025
Last Modified: October 23rd, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)